<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecurityCurve &#187; Legal Shiz</title>
	<atom:link href="http://www.securitycurve.com/wordpress/archives/tag/legal-shiz/feed" rel="self" type="application/rss+xml" />
	<link>http://www.securitycurve.com/wordpress</link>
	<description></description>
	<lastBuildDate>Mon, 06 Feb 2012 17:05:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>“Dude, you’re gettin’ a Dell.”  And by Dell, I mean a pointy stick in the eye</title>
		<link>http://www.securitycurve.com/wordpress/archives/1730?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dude-youre-gettin-a-dell-and-by-dell-i-mean-a-pointy-stick-in-the-eye</link>
		<comments>http://www.securitycurve.com/wordpress/archives/1730#comments</comments>
		<pubDate>Wed, 30 Jun 2010 13:10:30 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Evil]]></category>
		<category><![CDATA[Legal Shiz]]></category>
		<category><![CDATA[The Law: Fear It]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=1730</guid>
		<description><![CDATA[Welcome our newest candidate for &#8220;dark lord of the pit&#8221;, Dell. According to court documents, they knowingly sold faulty computers and covered it up for years.  Despicable. What bothers me the most about this is the callous attitude that Dell had for the security, safety, and livelihood of the folks they sold to; from betanews: [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><img class="alignright" src="http://weirdnewsfiles.com/wp-content/weirdnewsuploads/satan.jpeg" alt="" width="300" height="200" />Welcome our newest candidate for &#8220;dark lord of the pit&#8221;, Dell.  According to court documents, <a href="http://www.nytimes.com/2010/06/29/technology/29dell.html?adxnnl=1&amp;src=busln&amp;adxnnlx=1277902852-8G5JpxLwlS1VVVFa19bhyQ" target="_blank">they knowingly sold faulty computers</a> and <a href="http://www.betanews.com/article/Unsealed-court-documents-reveal-Dell-knew-it-sold-faulty-computers/1277845742?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+bn+(Betanews+Full+Content+Feed+-+BN)" target="_blank">covered it up</a> for years.  Despicable.</p>
<p>What bothers me the most about this is the callous attitude that Dell had for the security, safety, and livelihood of the folks they sold to; from betanews:</p>
<blockquote><p>Capacitors had been known to leak, and in some cases could pose a fire risk. The problems also posed a data loss risk, although the computer manufacturer made a concerted effort to play down any possible issues.</p></blockquote>
<p>Nice.  The NY Times continues the festival:</p>
<blockquote><p>Crucially, in their complaints to Dell in the lawsuit, customers describe losing valuable information when their computers malfunctioned. Dell, by contrast, denied that that the capacitor issue had caused data loss.</p></blockquote>
<p>So, Dell: putting us all at risk to cover their shame&#8230;  It&#8217;s just not right.</p>
<div class="shr-publisher-1730"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1730' data-shr_title='%E2%80%9CDude%2C+you%E2%80%99re+gettin%E2%80%99+a+Dell.%E2%80%9D++And+by+Dell%2C+I+mean+a+pointy+stick+in+the+eye'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1730' data-shr_title='%E2%80%9CDude%2C+you%E2%80%99re+gettin%E2%80%99+a+Dell.%E2%80%9D++And+by+Dell%2C+I+mean+a+pointy+stick+in+the+eye'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/1730/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US Government: Serving up whale for over 100 years</title>
		<link>http://www.securitycurve.com/wordpress/archives/1661?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=us-government-serving-up-whale-for-over-100-years</link>
		<comments>http://www.securitycurve.com/wordpress/archives/1661#comments</comments>
		<pubDate>Fri, 25 Jun 2010 13:05:36 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>
		<category><![CDATA[Stealing Stuff]]></category>
		<category><![CDATA[The Law: Fear It]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=1661</guid>
		<description><![CDATA[Interesting&#8230;  If you haven&#8217;t seen the coverage, the FTC forced Twitter to update its information security program after a slew of information security issues including password problems, breaches, and fraudulent claims about the security of the site (in other words,  claimed protection measures that just weren&#8217;t implemented the way they said they were).  Check it out: [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p style="text-align: left;"><img class="alignright" src="http://blogs.nature.com/news/thegreatbeyond/whale%20meat%20NOAA.jpg" alt="" width="333" height="225" />Interesting&#8230;  If you haven&#8217;t seen the coverage, the FTC forced Twitter to <a href="http://www.scmagazineus.com/ftc-forces-twitter-to-upgrade-its-it-security-program/article/173169/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+SCMagazineNews+(SC+Magazine+News)" target="_blank">update its information security program</a> after a slew of information security issues including<a href="http://www.networkworld.com/news/2010/062410-twitter-settles-ftc-privacy.html?source=nww_rss" target="_blank"> password problems</a>, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1515624,00.html?track=sy160" target="_blank">breaches</a>, and <a href="http://www.theregister.co.uk/2010/06/24/twitter_ftc_settlement/" target="_blank">fraudulent claims about the security of the site</a> (in other words,  claimed protection measures that just weren&#8217;t implemented the way they said they were).  Check it out:</p>
<blockquote><p>In one case, attackers were able to exert administrative control over the site, which enabled them to deliver bogus tweets pretending to originate from the accounts of a number of well-known members, including President Obama.</p></blockquote>
<p style="text-align: left;">Hah!  It&#8217;s never any good when you let shady characters post content as the president of the US.  Semi-related, but in epic bad timing, a researcher <a href="http://www.scmagazineus.com/researcher-demonstrates-twitter-xss-vulnerability/article/173168/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+SCMagazineNews+(SC+Magazine+News)" target="_blank">demonstrated XSS issues</a> in the platform&#8230; that&#8217;s not good.</p>
<p style="text-align: left;">Anyway, this is interesting to me in that the FTC should choose to exercise its muscle for cleaning up Twitter. I mean, they&#8217;ve gone <a href="http://www.ftc.gov/privacy/privacyinitiatives/promises_press.html" target="_blank">after others in the past</a> &#8211; but this is one of the relatively few in that there wasn&#8217;t actual cash at stake.  So&#8230; props to the FTC for taking the situation seriously.  No question that there were some serious issues and failure to uphold their security claims.  But I&#8217;m surprised at how forward thinking this is of them &#8211; most regulatory bodies are fairly slow to react.  Good job, FTC.</p>
<p style="text-align: left;">So, next stop: farmville?  I hear it&#8217;s a seedy underbelly of animal cruelty and lax agricultural safeguards&#8230;</p>
<div class="shr-publisher-1661"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1661' data-shr_title='US+Government%3A+Serving+up+whale+for+over+100+years'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1661' data-shr_title='US+Government%3A+Serving+up+whale+for+over+100+years'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/1661/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Restaurateurs, SIs, and PCI</title>
		<link>http://www.securitycurve.com/wordpress/archives/1338?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=restaurateurs-sis-and-pci</link>
		<comments>http://www.securitycurve.com/wordpress/archives/1338#comments</comments>
		<pubDate>Mon, 11 Jan 2010 13:33:52 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=1338</guid>
		<description><![CDATA[Dan Kaplan has a piece in SC Magazine on the lawsuit being filed against SI/resellers Radiant Systems and Computer World by some restaurants in Louisian and Mississippi. Dan interviewed me for the piece: Diana Kelley, founder of consultancy Security Curve, said she understands where the restaurants have a case, considering Visa alerted the two defendants [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Dan Kaplan has <a href="http://www.scmagazineus.com/pci-merchants-take-on-providers/article/160022/">a piece in SC Magazine</a> on the lawsuit being filed against SI/resellers Radiant Systems and Computer World by some restaurants in Louisian and Mississippi.</p>
<p>Dan interviewed me for the piece:</p>
<blockquote><p>Diana Kelley, founder of consultancy Security Curve, said she understands where the restaurants have a case, considering Visa alerted the two defendants in April 2007 that their systems were non-compliant. The eateries claimed they never learned of the warning, but Kelley said they still are required to perform a PCI assessment, which should have caught the vulnerabilities.</p>
<p> “We&#8217;re going to have a judge put some case law on where the accountability does lie,” she said. “It really could change the landscape.” </p></blockquote>
<div class="shr-publisher-1338"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1338' data-shr_title='Restaurateurs%2C+SIs%2C+and+PCI'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1338' data-shr_title='Restaurateurs%2C+SIs%2C+and+PCI'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/1338/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Really CIS?</title>
		<link>http://www.securitycurve.com/wordpress/archives/1160?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=really-cis</link>
		<comments>http://www.securitycurve.com/wordpress/archives/1160#comments</comments>
		<pubDate>Tue, 02 Jun 2009 04:08:31 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>
		<category><![CDATA[Mouth-Frothing]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=1160</guid>
		<description><![CDATA[OK, so I saw in the industry press that CIS had put out configuration guidance for the iPhone. This seemed interesting to me, since I&#8217;m now an Android user (love it, by the way) &#8211; I think the Google phone is the best thing since sliced bread. Not that the iPhone and Android are the [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><img src="http://www.tentonhammer.com/system/files/images/300px-happy_fun_ball.jpg" align=right hspace=5 vspace=5>OK, so I saw <a href="http://www.cellular-news.com/story/37744.php">in the industry press that CIS had put out configuration guidance for the iPhone.</a>  This seemed interesting to me, since I&#8217;m now an Android user (love it, by the way) &#8211; I think the Google phone is the best thing since sliced bread.  Not that the iPhone and Android are the same thing &#8211; just because I feel a kinship with the iPhone users for some reason.</p>
<p>Anyway, I surfed over to <a href="https://www.cisecurity.org/tools2/iphone/CIS_iPhone_2.2.1_Benchmark_v1.0.0.pdf">the benchmark</a> to check it out.  Not surprisingly, there&#8217;s about as much complexity associated with hardening an iPhone as you&#8217;d probably expect.  For example, they outline that &#8220;Airplane Mode&#8221; is pretty good from a security perspective,  that it&#8217;s probably a good idea to turn the password protection feature on, and that you really ought to upgrade the firmware occasionally.  </p>
<p>But believe it or not, I didn&#8217;t bring it up to make fun of the specific recommendations in the benchmark.  It it what it is&#8230;  No matter how obvious the recommendations might seem to us as security folks, explicitly pointing stuff out in a no-nonsense way can never be bad.  </p>
<p>No, actually the reason I&#8217;m bringing this up comes about because of the &#8220;wall of text&#8221; in the legalese of the Benchmark&#8217;s Terms of Use.  Check this out and see if anything about this strikes you as unusual:</p>
<blockquote><p>CIS makes no representations&#8230; as to (i) the positive or negative effect of the Products or the Recommendations on the operation or the security of any particular network, computer system, network device, software, hardware&#8230;</p></blockquote>
<p>Wait&#8230;  wut?  OK, so I&#8217;m not a lawyer.  And maybe lawyers have a different meaning for the word &#8220;representation&#8221; (if so, I <a href="http://legal-dictionary.thefreedictionary.com/Representation">couldn&#8217;t find it</a>).  But doesn&#8217;t this (from the CIS Benchmark FAQ) sound like a representation &#8220;as to the positive effect&#8221; on security:</p>
<blockquote><p>CIS Benchmarks enumerate security configuration settings and actions that &#8220;harden&#8221; your systems. They are unique, not because the settings and actions are unknown to any security specialist, but because consensus among hundreds of security professionals worldwide has defined these particular configurations.</p></blockquote>
<p>What bothers me about this is that CIS <strong>clearly</strong> asserts that using the benchmarks will help secure your systems.  What else could &#8220;harden your systems&#8221; mean?  What would be the point of pointing out that &#8220;hundreds of experts agree&#8221; if the end state was not to make the security profile better?  </p>
<p>It&#8217;s clearly the case.  In fact, it&#8217;s sort of the whole point.  </p>
<p>CIS leading with this seems to me kind of like Honda pasting a big yellow sticker on the Civic&#8217;s steering wheel that says &#8220;Automobile not intended for transportation.&#8221;  &#8230;  What the frick else would it be intended for?  Outdoor paperweight?  Portable cell-phone charger?  </p>
<p>Is it really the case that we&#8217;re so far down the word-weasel road that the only way not to get sued is to entirely disavow what our products actually do?  Can it really be that bad?  Or is CIS just over the fence?</p>
<div class="shr-publisher-1160"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1160' data-shr_title='Really+CIS%3F+'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F1160' data-shr_title='Really+CIS%3F+'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/1160/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A higher standard for security pros?</title>
		<link>http://www.securitycurve.com/wordpress/archives/534?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=a-higher-standard-for-security-pros</link>
		<comments>http://www.securitycurve.com/wordpress/archives/534#comments</comments>
		<pubDate>Tue, 20 Jan 2009 18:17:25 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>

		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=534</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><img src="http://www.fantasticfiction.co.uk/images/n44/n220422.jpg" align=right hspace=5 vspace=5 width=50% height=50%>So, today I came across a small reference (via HackInTheBox) about <a href="http://www.vnu.co.uk/vnunet/news/2214044/uk-top-computer-forensics#commentsModule">how one of the UK&#8217;s premier forensics experts</a> committed perjury by claiming to have a degree that he didn&#8217;t, in point of fact, have.</p>
<p>It barely made a blip in the press &#8211; after all, it wasn&#8217;t a huge sentence (he got a suspended sentence and a small fine), his colleagues say that there was no doubt as to his expertise, and that he didn&#8217;t put any convictions in jeopardy.</p>
<p>Now, I&#8217;m not going to be the first in line to pile all over him and say that he was wrong or &#8220;a monster&#8221; or evil or whatever&#8230; Human nature is what it is, and people lie from time to time.  So he didn&#8217;t have a degree?  So what&#8230;  On the punishment side, the court did a pretty good job with the sentencing.  A small sentence, but one that makes it very unlikely that he&#8217;ll be an expert witness again, thereby preventing recurrence.  So it goes.</p>
<p>But what interests me about this is the long-term effect that misdeeds on the part of security folks have.  Take, for example, the recent <a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/12/07/MNIK147QU3.DTL&#038;feed=rss.news">Pay By Touch debacle</a> (you know, where the CEO was playing fast and loose by running biometric payments into the ground).  I liked Pay By Touch &#8211; sort of.  I thought it was a good idea, but I figured it was going to flop &#8211; although I figured it was doomed because of the sales numbers they had on their site (which were clearly bogus) as opposed to the whole fraud/drug use/sex parties thing.</p>
<p>Anyway, the point is this &#8211; after Pay By Touch, how likely is it that supermarkets &#8211; or the populace as a whole for that matter &#8211; will trust biometrics nowadays?  Sure, maybe they&#8217;ll trust the biometric technology &#8211; but there could be some lingering suspicion for the companies.  Will that bad will extend to other security companies and products?  Maybe so.  Will practicing forensics in the UK be harder now that it turns out the &#8220;founder&#8221; of the discipline in that region was lying to the court?  I would tend to think so&#8230;</p>
<p>So, I guess I&#8217;ll stop ranting now&#8230; I just find it irritating when the actions of an individual make everyone else feel the pain.  Maybe at some point we&#8217;ll all wake up and start enforcing competency (and ethics) for the discipline the same way they do with medical practitioners.  Or maybe not&#8230;</p>
<div class="shr-publisher-534"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F534' data-shr_title='A+higher+standard+for+security+pros%3F'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F534' data-shr_title='A+higher+standard+for+security+pros%3F'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/534/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Massachusetts &#8211; 6 Million People Can&#8217;t be Wrong</title>
		<link>http://www.securitycurve.com/wordpress/archives/528?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=massachusetts-6-million-people-cant-be-wrong</link>
		<comments>http://www.securitycurve.com/wordpress/archives/528#comments</comments>
		<pubDate>Tue, 02 Dec 2008 21:15:51 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>

		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=528</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><img src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/7f/Seal_of_the_State_of_Massachusetts.svg/100px-Seal_of_the_State_of_Massachusetts.svg.png" align=right hspace=5 vspace=5>Hey, so have you been keeping up with all the awesomeness going on in Mass?  In case you haven&#8217;t noticed, there&#8217;s a bunch of new stuff out there.  There&#8217;s <a href="http://www.mass.gov/?pageID=ocamodulechunk&#038;L=1&#038;L0=Home&#038;sid=Eoca&#038;b=terminalcontent&#038;f=idtheft_201cmr17&#038;csid=Eoca">201 CMR 17.00</a> which requires encryption of personal data of a commonwealth resident no matter where it is.  That&#8217;s pretty awesome, and it&#8217;s going to blow a hole in traditional IT.  After all, how do you know who&#8217;s a resident of Mass or not?  Couldn&#8217;t someone list their secondary address in your database, but really be a resident of Mass?  Sure.  Would they be covered by the law?  Probably.  Nifty, huh?  It&#8217;s the same dilemma that businesses were in relative to SB-1386.  And we all know how that shook out.</p>
<p>But what&#8217;s even cooler than that (or maybe just as cool) is <a href="http://www.mass.gov/Eoca/docs/idtheft/eo504.pdf">Executive Order 504</a> that requires specific information security controls, management, and governance from state agencies, and requires certification of contractors to a defined security standard.  Again, this ought to shake things up a bit.</p>
<p>I&#8217;m really pleased with what&#8217;s going on just down south of us.  Although I&#8217;m a little nervous.  Here&#8217;s why:</p>
<p>1) we&#8217;re heading in to a recession<br />
2) recession means less tax money to the government<br />
3) recession means higher unemployment and higher rate of state-funded programs like unemployment<br />
4) states have to maintain a <a href="http://www.ncsl.org/programs/fiscal/balreqs.htm">balanced budget</a><br />
5) more technical controls means more IT spending at the expense of services-spending</p>
<p>I&#8217;m not sure that this is the perfect time for what Mass is up to &#8211; but I&#8217;m really interested to see how it&#8217;ll shake out.</p>
<div class="shr-publisher-528"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F528' data-shr_title='Massachusetts+-+6+Million+People+Can%27t+be+Wrong'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F528' data-shr_title='Massachusetts+-+6+Million+People+Can%27t+be+Wrong'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/528/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Time to sue Bruce?</title>
		<link>http://www.securitycurve.com/wordpress/archives/277?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=time-to-sue-bruce</link>
		<comments>http://www.securitycurve.com/wordpress/archives/277#comments</comments>
		<pubDate>Wed, 16 Nov 2005 19:14:31 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>

		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=277</guid>
		<description><![CDATA[Remember the other day when I was talking about why assigning liablity for buggy code was a bad idea? Bruce had argued that we should sue companies for buggy software &#8211; which I argued was not a good idea because smaller companies that made freeware tools (e.g. Counterpane) wouldn&#8217;t release such a tool given the [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Remember the other day when I was <a href="http://www.securitycurve.com/blog/archives/000263.html">talking about why assigning liablity for buggy code was a bad idea?</a>  Bruce had argued that we should sue companies for buggy software &#8211; which I argued was not a good idea because smaller companies that made freeware tools (e.g. Counterpane) wouldn&#8217;t release such a tool given the risk.  Well, as if to prove my point, the folks over at Elcomsoft (remember them) pointed out what is arguably <a href="http://archives.neohapsis.com/archives/vuln-dev/2005-q4/0037.html">a security flaw in PasswordSafe.</a>  I say &#8220;arguably&#8221; because it&#8217;s a &#8220;how to make a dictionary attack viable&#8221; kind of flaw; Microsoft argued this wasn&#8217;t a flaw <i>per se</i> when the same thing happened to them (with L0phtcrack) so maybe it&#8217;s not a flaw here either.</p>
<p>If we all followed the &#8220;company liability&#8221; model, now would be the time to start getting our class action together against CounterPane; if we followed the &#8220;developer liability&#8221; model, I suppose we would need to sue Bruce himself.  In my opinion, both are obviously foolish &#8211; nobody cares more about security than Bruce Schneier&#8230; Why sue him for someone else&#8217;s creativity?</p>
<div class="shr-publisher-277"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F277' data-shr_title='Time+to+sue+Bruce%3F'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F277' data-shr_title='Time+to+sue+Bruce%3F'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/277/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Crank Yankers, Bill Clinton, and Digital Privacy</title>
		<link>http://www.securitycurve.com/wordpress/archives/177?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=crank-yankers-bill-clinton-and-digital-privacy</link>
		<comments>http://www.securitycurve.com/wordpress/archives/177#comments</comments>
		<pubDate>Thu, 09 Jun 2005 16:14:38 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>

		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=177</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Everybody&#8217;s heard about the now-infamous <a href="http://www.theregister.co.uk/2005/02/21/paris_hacked/">Paris Hilton sidekick incident</a>.  It&#8217;s been the subject of numerous <a href="http://www.liquidgeneration.com/games/paris_cellphone.asp">Internet parodies</a>, television hijinkery, and entertainment gossip.  Apparently, in a similar incident, Jimmy Buffet&#8217;s phone was stolen by a restaurant busboy and used to <a href="http://www.thesmokinggun.com/archive/0608052_jimmy_buffett_1.html">&#8220;crank yank&#8221; former president Bill Clinton</a>.</p>
<p>So where am I going with this?  Who cares, right?  Everybody nowadays has a cell phone, PDA, sidekick, nomad, iPod, or some other easily-misplaced digital information appliance.  We use them to store everything: pictures, phone numbers, music, plans to the death star, etc.  One often-overlooked fact in all this is that these devices of today are more and more frequently starting to obviate the privacy measures of yesterday.  In other words, Bill Clinton thought his number was unlisted and inaccessible to the casual prank caller; it was, and it would have stayed that way if it weren&#8217;t for a lost cell phone half a hemisphere away.</p>
<p>There are three trends at work: 1) these unsecured devices are starting to carry more data and more types of data.  2) these devices are becoming more ubiquitous.  3) any data on these devices can be (as was the case with Paris&#8217; data) instantaneously shared amongst interested parties across the globe.  I think, looking down the road, that privacy erosion is less about government &#8220;big brother&#8221; (as argued by Orwell) or the numerous corporate &#8220;little brothers&#8221; (although this is slightly more prevalent.)  After all, pro-privacy folks at least have a chance to fight back on those fronts.  What scares me much more is the large array of personal &#8220;micro brothers&#8221; &#8211; the &#8220;Amway&#8221;-tization of privacy loss.  By the time anybody notices, there will be no such thing as an &#8220;unlisted number&#8221;, &#8220;private IM account&#8221;, or anonymous email address; how can there be when all this data is stored in so many different places and can be instantly shared?  Call me cynical, but I think it&#8217;s only a matter of time; for the truth of this, just ask all the famous people who had to change their number as a result of Paris&#8217; hacked side-kick account &#8211; or ask Bill Clinton for that matter.  You can still find their phone numbers on Google.</p>
<div class="shr-publisher-177"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F177' data-shr_title='Crank+Yankers%2C+Bill+Clinton%2C+and+Digital+Privacy'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F177' data-shr_title='Crank+Yankers%2C+Bill+Clinton%2C+and+Digital+Privacy'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/177/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Passwords not enough?</title>
		<link>http://www.securitycurve.com/wordpress/archives/151?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=passwords-not-enough</link>
		<comments>http://www.securitycurve.com/wordpress/archives/151#comments</comments>
		<pubDate>Fri, 15 Apr 2005 16:33:42 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>

		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=151</guid>
		<description><![CDATA[Typically, I come down on the side of &#8220;sufficient protection&#8221; when debating what type of authentication mechanism to employ in a given security scenario. Up until now, that meant that I felt that passwords were a fairy robust vehicle for protecting data. However, a recent ruling determined that passwords alone were insufficient protection to preserve [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Typically, I come down on the side of &#8220;sufficient protection&#8221; when debating what type of authentication mechanism to employ in a given security scenario.  Up until now, that meant that I felt that passwords were a fairy robust vehicle for protecting data.  However, <a href="http://www.internetcases.com/2005/04/password-protection-not-enough-to.html">a recent ruling determined that passwords alone were insufficient protection to preserve trade secret information</a>.  In other words, data placed in a directory secured by passwords was found to <strong>not</strong> be sufficient protection to preserve trade-secret status.  In this instance, the judge questioned why other measures weren&#8217;t taken &#8211; e.g. data labeling, confidentiality notices, etc.</p>
<p>In context, I agree with the ruling.  While what the judge said is true (e.g. that the employees of the firm needed to be advised of data confidentiality,) I&#8217;m concerned about the precedent and how the industry will react.  The judge said in his ruling, &#8220;[r]estricting access to sensitive information by assigning employees passwords on a need-to-know basis is a step in the right direction&#8221;.  &#8220;a step in the right direction&#8221; but not &#8220;sufficient.&#8221;  What is sufficient?  A confidentiality label at the bottom of the screen?  I don&#8217;t think that will cut the mustard if passwords don&#8217;t&#8230;</p>
<p>This is just the kind of thing that a unscrupulous company could spin into a FUD-fest to try to sell two-factor products.</p>
<div class="shr-publisher-151"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F151' data-shr_title='Passwords+not+enough%3F'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F151' data-shr_title='Passwords+not+enough%3F'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/151/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;chaotic&#8221; and &#8220;a litigation bonanza&#8221;</title>
		<link>http://www.securitycurve.com/wordpress/archives/112?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=chaotic-and-a-litigation-bonanza</link>
		<comments>http://www.securitycurve.com/wordpress/archives/112#comments</comments>
		<pubDate>Mon, 25 Aug 2003 12:58:41 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Legal Shiz]]></category>

		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=112</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Quotes from FCC Chairman Michael Powell on the FCC&#8217;s rules released on local telephone and broadband: <a href="http://www.eweek.com/article2/0,3959,1229071,00.asp?kc=EWRSS02129TX1K0000531"> &#8220;FCC Releases Rules on Local Phone, Broadband Competition.&#8221;</a></p>
<p>Makes you wonder when the Chairman has such an uncomplimentary view of the rules.  A lot of the rules pertain to discounts and sharing requirements of existing networks.  If you&#8217;re interested in the full report, the FCC has all 576 pages available for download here: <a href="http://www.fcc.gov">www.fcc.gov</a>, along with comments from Powell, and Commissioners: Abernathy, Copps, Martin and Adelstein.</p>
<div class="shr-publisher-112"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F112' data-shr_title='%22chaotic%22+and+%22a+litigation+bonanza%22'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F112' data-shr_title='%22chaotic%22+and+%22a+litigation+bonanza%22'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/112/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

